Virus Database


T_Power family

Description T_Power family

These are dangerous memory resident encrypted parasitic viruses. They hook INT 1Ch, 21h, and on file opening, execution and creating these viruses search for COM and EXE files and write themselves to the end of the file. The viruses do not infect several anti-virus programs, they also search for some anti-virus data files and delete them. Depending on their internal counter "T_Power.Cowa" reboots the computer, "T_Power.Zarma" disables/enables the video refresh. The viruses contain the text strings:
OMSPEC=
*.COM *.EXE
SMART*.* CHK*.* ANTI-VIR.DAT *.VIR NAV_._*
SCAN F- VIR VSH AV .S BMB BMD TB IM IV

They also contain the strings:
"T_Power.Cowa": COWA-BUNGA VIRUS (C) 1994 by Turbo Power *** Claudia
Schieffer Lives !!!
"T_Power.Sodo": [Sodomizator/T.Power] Do you like me ?
"T_Power.Zarma": ZARMA-VIR by T.Power *** Claudia Schiffer Lives !!!

Check other viruses! Be aware! Use Antiviral Software

Kiuca family

Description Kiuca family

These are harmless memory resident multipartite viruses. They infect COM and EXE files as well as the boot sector of C: drive. When an infected file is executed, the viruses infect the hard drive - they write their code and the original boot sector of C: disk to the track/head 0/0 on the hard drive and overwrite the C: disk boot sector with their loading routine.
While loading from infected hard drive the virus copies itself to the top of system memory, hooks INT 1Ch, waits for DOS loading process, then hooks INT 21h and when any program is executed, completes installation routine - allocates a blocks of DOS memory and copies itself to there. As a result the virus does not decreases the total size of DOS memory, but places itself between DOS kernel and COMMAND.COM. The virus then writes itself to the end of COM and EXE files that are created and then closed.
The virus several tricks to avoid detection by integrity (CRC) checker. It infects only newly created files, or files that are restored from archives of backup, as a result there is no information about these files in CRC databases. To hide infected boot sector the virus disinfects it when any program (including anti-viruses) is executed, and re-infects on termination. As a result the disk boot sector is infected only when there are no programs in the system memory.
The virus contains the text strings in Russian and English:
(c) Light General.Kiev.KIUCA.1996.NOT for free use.

Kiwi.550

Description Kiwi.550

It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files. It contains the text:
I'm KIWI-586.(C) Vegetable-Soft,1992.DOS AIDSTEST

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com